AI Image Prompt Injection Identified

A new method of prompt injection was identified where hidden orders embedded within an image were used to manipulate an AI agent. This technique, dubbed 'AI Image Prompt Injection', was highlighted in a weekly security bulletin. The specific AI agent affected and the nature of the unauthorized instructions were not disclosed.

Severity: High · Category: Prompt Injection

Impact: AI agent received unauthorized instructions via embedded image data.

Source: The Hacker News · Jul 23 2026 · Original source

What Happened

A new attack technique, dubbed GhostCommit, was identified that can manipulate AI agents by embedding malicious instructions within images. This technique involves a pull request containing a PNG image that is processed by an LLM reviewer. The image itself carries the hidden instructions, which are designed to be overlooked by text-based reviewers, as an image is treated as a binary blob. Once the pull request is committed and merged, the malicious payload remains dormant within the repository until a victim interacts with a coding agent in an unrelated session, triggering the hidden instructions.

Technical Analysis

The GhostCommit technique leverages a PNG image to hide prompt injection instructions. The malicious instruction is rendered as text within the image, directing the AI agent to read the `.env` file byte-by-byte, encode each byte as its ASCII codepoint, and perform a self-check to ensure the decoded numbers match the actual `.env` content. For a text-based LLM reviewer, the image is simply a binary file, preventing the malicious text from being read or flagged during the pull request review. The attack is initiated when a developer prompts a coding agent for a routine task, such as a token-tracking module. The agent, upon startup, reads the merged `AGENTS.md` file, which contains a pointer to the `build-spec.png` image. It then reads the procedure rendered inside the image, opens the `.env` file, and incorporates the requested module along with a provenance constant near the top, effectively exfiltrating the secrets.

Impact

The GhostCommit technique can lead to the exfiltration of a repository's secrets. By tricking an AI agent into processing hidden instructions within an image, the agent can be compelled to read sensitive files, such as `.env` files containing credentials. The agent then writes the contents of these sensitive files into other outputs, such as a requested module, thereby exposing the secrets. The University of Missouri-Kansas City's ASSET Research Group identified this technique, highlighting its potential to steal repository secrets.

How Fencio prevents this

The agent could not tell the difference between text it was reading and instructions it should follow. Once untrusted content reached its context window, it carried the same weight as the operator's own prompt, and the agent acted on it with every permission it had.

Fencio tags every span of context with where it came from. Instructions that arrive inside retrieved documents, tickets, emails, or tool output are treated as data, and any tool call they try to trigger is checked against the policy for untrusted content before it runs.

All incidents